Technology and Informatics Insight Journal
Vol. 5 No. 2 (2026): TIIJ

Analisis Keamanan Strategi Autentikasi JWT pada Arsitektur API Gateway-IoT: Pendekatan STRIDE

Helmi Bahar Alim (Universitas Putra Bangsa)
Ari Subowo (Universitas Putra Bangsa)
Miftahul Huda (Universitas Putra Bangsa)



Article Info

Publish Date
30 Aug 2026

Abstract

Security authentication is a primary challenge in IoT systems relying on resource-constrained devices. JSON Web Token (JWT) is widely adopted as a stateless authentication mechanism, yet the choice of signing algorithm—RS256, ES256, HS256, or Delegated Auth—carries different security implications. This study analyzes four strategies using STRIDE on a Go/Echo-based API Gateway-IoT architecture with ESP8266 NodeMCU V3 devices, per system component. RS256 and ES256 have the smallest blast radius since private keys are per-device, while HS256 is vulnerable to mass exposure if the gateway database is compromised. Delegated Auth offers fastest revocation via gateway blacklist but inherits HS256's shared-secret weaknesses. Empirical data from 1,260 runs show ES256 requires 248.98 ms to sign a JWT (488× slower than HS256 at 0.51 ms), while RS256 is inoperable due to watchdog timer crashes (>8 seconds). These findings guide IoT system designers in selecting JWT strategies suited to their risk profile and device capabilities.

Copyrights © 2026






Journal Info

Abbrev

tiij

Publisher

Subject

Computer Science & IT

Description

The TIIJ (Technology and Informatics Insight Journal) publishes research from various topics in Informatic Technolgy and Computer Science, including but is not limited to the following topics: Mobile & Web Technology User Interface (UI) & User Experience (UX) Game Multimedia Machine Learning ...